Solved

App Locker Path Exception issue

Posted on 2013-11-05
2
2,210 Views
Last Modified: 2013-11-05
I'm using App Locker to secure my workstations, primarily as an anti-malware step, and it works very well.

I now have a new piece of software, that upon login, copies a batch file to the users %TEMP% directory, and runs it.

Of course, that's one of the directories that I have prevented batch files from running, so now I'm trying to allow just this batch file to run, as I know it is known good.  I cannot change the location where this batch file runs, the software maker does not allow for that type of modification.

Oh, and to just make it slightly harder, when the software copies the batch file to the TEMP dir, it uses a new file name every time (however there is a consistent file naming convention, so I'm hoping to use that to key in on this)

Here is what I've done.  I create an App Locker script deny rule, that denies scripts from running from this directory:

%OSDRIVE%\Users\*\AppData\Local\Temp\*

That works beautifully.  No batch files (or any other scripts) can run.

Next step, allow all batch files by putting in this exception:

%OSDRIVE%\Users\*\AppData\Local\Temp\*.bat

That also works perfectly.  All batch files can run, but no other scripts.

Last step is to pin it down to only the known good batch files, that get copied upon login.  The batch files are always named like this:  "ABC12ws.bat" or "ABCh42s.bat".  The common thread is they always start with "ABC" then followed by 4 randomly generated characters, then the .bat.

So I thought I could easily modify my exception like this:

%OSDRIVE%\Users\*\AppData\Local\Temp\ABC*.bat

Unfortunately, for some reason, that allows all batch files to still be run.  My guess is it sees the wildcard, and just ignores the fact that I have 3 characters preceding it.

Is there a way I can put in an exception to my path rule, that will let me run batch files that use the name ABCxxxx.bat but block all other batch files?

Thanks
0
Comment
Question by:Vjz1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 

Accepted Solution

by:
Vjz1 earned 0 total points
ID: 39625045
I've resolved this on my own guys.

While the file name exactly is "Abc1234.bat" App Locker interprets the name to be "ABC1234.bat"  I know this because I looked at the event log on the workstation and saw the block entry.

Once I changed my rule to use "ABC*.bat" as the exception, instead of "Abc*.bat' everything works perfectly.
0
 

Author Closing Comment

by:Vjz1
ID: 39625047
I resolved the issue on my own.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question